CVE-2014-5083
HIGHsphider < 1.3.6 - Remote Code Execution via fwrite to conf.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5083.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple vulnerabilities in Sphider Search Engine, including authentication bypass, SQL injection, and remote code execution. It provides proof-of-concept examples and explains the root causes, such as lack of input sanitization and insecure file writing.
Description
A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5083 pertains to instances of fwrite in Sphider.
Exploits (1)
This is a detailed technical writeup describing multiple vulnerabilities in Sphider Search Engine, including authentication bypass, SQL injection, and remote code execution. It provides proof-of-concept examples and explains the root causes, such as lack of input sanitization and insecure file writing.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H